Splunk search for Get detailed information on Linux cron jobs
Copy
sourcetype=cron | rex ".*:\d{2}\s(?<host_name>\S+)" | rex "]:\sfinished(?<info>.*)" | stats count by host_name, info
This search will output a table of linux cron jobs that have run during the given search window. The table will include the number of times the cron job has run, the name of the cron job and the host it was run on.